Bug ID 756538: Failure to open data channel for active FTP connections mirrored across an HA pair.

Last Modified: Mar 12, 2019

Bug Tracker

Affected Product:  See more info
BIG-IP LTM(all modules)

Known Affected Versions:
12.1.0, 12.1.0 HF1, 12.1.0 HF2, 12.1.1, 12.1.1 HF1, 12.1.1 HF2, 12.1.2, 12.1.2 HF1, 12.1.2 HF2, 12.1.3, 12.1.3.1, 12.1.3.2, 12.1.3.3, 12.1.3.4, 12.1.3.5, 12.1.3.6, 12.1.3.7, 12.1.4, 13.1.0, 13.1.0.1, 13.1.0.2, 13.1.0.3, 13.1.0.4, 13.1.0.5, 13.1.0.6, 13.1.0.7, 13.1.0.8, 13.1.1, 13.1.1.1, 13.1.1.2, 13.1.1.3, 13.1.1.4, 14.0.0, 14.0.0.1, 14.0.0.2, 14.0.0.3, 14.0.0.4, 14.1.0, 14.1.0.1, 14.1.0.2

Opened: Jan 25, 2019
Severity: 3-Major

Symptoms

Occasionally, attempting to actively open a data channel from an FTP session that is mirrored across a BIG-IP HA pair will fail. This is due to aggressive port reuse on the active BIG-IP causing ports that are still in a TIME_WAIT state to be used for the data connection.

Impact

Data connections fail to open, data transfer is unsuccessful.

Conditions

- Have a BIG-IP HA pair configured - Create an FTP virtual server with mirroring enabled - Have the pool member(s) of the virtual server be either 3CDaemon or IIS servers (this issue has only been found for 3CDaemon and IIS, but it could affect other servers as well). - Client attempts to download data through the virtual server via active FTP.

Workaround

Use passive FTP, or do not use mirroring for FTP virtual servers.

Fix Information

None

Behavior Change